
trivy-action
Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

layerleak the Docker Hub Secret Scanner

Scans Docker Hub images using regex patterns to extract exposed secrets, private keys, and authentication tokens for security auditing and incident…

Detects CVE-2025-55182 RCE in React Server Components by scanning npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs. Includes auto-fix,…

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

A vulnerability scanner for container images and filesystems

Vulnerable app with examples showing how to not use secrets

:unlock: :unlock: Find secrets and passwords in container images and file systems :unlock: :unlock:

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

A project security/vulnerability/risk scanning tool

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Ah shhgit! Find secrets in your code. Secrets detection for your GitHub, GitLab and Bitbucket repositories.

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

Proper sandboxing for agentic coding and web browsing

Zero-code K8s sidecar for log sanitization. Detects secrets via Entropy Analysis, preserves JSON integrity, and redacts PII deterministically. 🛡️

harbor unauthorized detection